Comment Never Enable WAN Access (Score 3, Insightful) 23
The original announcement isn't clear, but based on the relatively low number of affected devices (there must be hundreds of thousands of these routers in use), it seems that only "savvy" users who enabled forms-based logins on the WAN port may have been affected.
Installing a private key and enabling SSH on a non-default port (as the attackers did) is likely much more secure, if the device absolutely must be accessible, or enabling the VPN -- again with public/private key pairs.